Skip to content

[FP]: CVE-2024-9329 shown for Old JAXB Runtime 4.0.7 #8374

@mo7ty

Description

@mo7ty

Package URl

pkg:maven/com.sun.xml.bind/jaxb-impl@4.0.7

CPE

cpe:2.3:a:eclipse:glassfish:4.0.7:::::::*

CVE

CVE-2024-9329

ODC Integration

{"label" => "Gradle Plugin"}

ODC Version

12.2.0

Description

CVE-2024-9329, affecting "Eclipse Glassfish versions before 7.0.17", is being reported for Old JAXB Runtime » 4.0.7, when the dependecy tree is shown as:

com.sun.xml.bind:jaxb-impl:4.0.7
\--- com.sun.xml.bind:jaxb-core:4.0.7
     +--- jakarta.xml.bind:jakarta.xml.bind-api:4.0.5
     \--- org.eclipse.angus:angus-activation:2.0.3
          \--- jakarta.activation:jakarta.activation-api:2.1.4

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions